Weakness Name | |
---|---|
CWE-1247 |
Improper Protection Against Voltage and Clock Glitches The device does not contain or contains incorrectly implemented circuitry or sensors to detect and mitigate voltage and clock glitches and protect sensitive information or software contained on the device. |
CWE-1248 |
Semiconductor Defects in Hardware Logic with Security-Sensitive Implications The security-sensitive hardware module contains semiconductor defects. |
CWE-1256 |
Improper Restriction of Software Interfaces to Hardware Features The product provides software-controllable device functionality for capabilities such as power and clock management, but it does not properly limit functionality that can lead to modification of hardware memory or register bits, or the ability to observe physical side channels. |
CWE-1319 |
Improper Protection against Electromagnetic Fault Injection (EM-FI) The device is susceptible to electromagnetic fault injection attacks, causing device internal information to be compromised or security mechanisms to be bypassed. |
CWE-1332 |
Improper Handling of Faults that Lead to Instruction Skips The device is missing or incorrectly implements circuitry or sensors that detect and mitigate the skipping of security-critical CPU instructions when they occur. |
CWE-1334 |
Unauthorized Error Injection Can Degrade Hardware Redundancy An unauthorized agent can inject errors into a redundant block to deprive the system of redundancy or put the system in a degraded operating mode. |
CWE-1338 |
Improper Protections Against Hardware Overheating A hardware device is missing or has inadequate protection features to prevent overheating. |
CWE-1351 |
Improper Handling of Hardware Behavior in Exceptionally Cold Environments A hardware device, or the firmware running on it, is missing or has incorrect protection features to maintain goals of security primitives when the device is cooled below standard operating temperatures. |
Name | Organization | Date | Date release |
---|---|---|---|
CAPEC Content Team | The MITRE Corporation |
Name | Organization | Date | Comment |
---|---|---|---|
CAPEC Content Team | The MITRE Corporation | Updated Attack_Motivation-Consequences | |
CAPEC Content Team | The MITRE Corporation | Updated @Abstraction | |
CAPEC Content Team | The MITRE Corporation | Updated Related_Weaknesses |